The job to be done
Restore trustworthy business services from a suitable recovery point even when production administration has been compromised.
Cyber recovery restores a trustworthy business service after an attacker has damaged systems or compromised the people and tools that administer them. A successful backup is only the starting point. The recovery design must preserve usable copies, protect their administrative boundary, choose a defensible recovery point and rebuild dependencies in a controlled environment. Recovery point objective describes tolerated data loss; recovery time objective describes tolerated interruption. Neither is proven by a product label. This guide separates enterprise backup platforms, isolated vaults, recovery orchestration and workload-specific services, then asks learners to demonstrate restoration with synthetic data.
What goes in
- Protected workload copies and recovery metadata
- Business recovery priorities and dependencies
- Administrative separation and integrity checks
What should come out
- Tested restoration evidence
- Recovery timing and data-loss observations
- Documented recovery ownership and remaining gaps
Inside the segment
These capabilities answer different questions. Use the distinction to define the work before assembling a shortlist.
Enterprise backup and recovery
Create policy-managed copies and restore supported machines, databases and files.
Boundary: A completed backup job does not prove application consistency, business functionality or independence from compromised administrators.
Isolated vaulting
Keep a copy under distinct access, retention and network controls.
Boundary: Logical isolation and scheduled connectivity are not the same as physically disconnected storage; verify the exact trust boundary.
Recovery orchestration and validation
Sequence dependencies, rehearse restoration and record whether a recovered service works.
Boundary: Starting a virtual machine is not a complete application test, and a malware scan cannot prove the absence of every compromise.
Cloud and SaaS recovery
Protect supported cloud resources or application objects and their recoverable metadata.
Boundary: A SaaS provider’s own resilience does not automatically satisfy your deletion, retention or granular restore requirements.
How the work flows
Define the minimum service
Select one synthetic business service and its identity, DNS, network, application and data dependencies. Record the required recovery time and acceptable loss in terms the service owner can test.
Separate the recovery authority
Map who can alter production, backup policy, retention, keys and recovery destinations. Establish recovery access that does not depend exclusively on the identity system being restored.
Protect and verify copies
Create a small backup and verify retention and destination settings. Exercise a denied deletion through a non-destructive authorization check or disposable lab, respecting irreversible retention settings.
Recover into an isolated target
Choose a documented recovery point, rebuild dependencies in order and preserve investigation evidence. Use synthetic data and keep the exercise from reconnecting to production systems.
Prove the service and improve the plan
Run a business transaction, compare known records, measure elapsed time and document missing permissions, keys or configuration. Clean up the test target and revise the runbook.
The environment changes the question
Use these scenarios to adapt the evaluation to your organization. They describe operational concerns, not a determination of compliance.
Finance ↗
Restore a synthetic payments service and reconcile its ledger to a known transaction boundary.
Evaluate: Measure recoverable data loss and transaction integrity, with independent approval before reconnecting the recovered service.
Utilities ↗
Recover a test historian and engineering workstation while the control environment remains isolated.
Evaluate: Include configuration, licensed software and safe operating procedures; data restoration alone cannot establish safe plant operation.
Manufacturing ↗
Rebuild a fictional production-scheduling service and verify its interfaces with warehouse and plant systems.
Evaluate: Sequence identity, database and application dependencies, then validate the work order rather than stopping at a powered-on VM.
Healthcare ↗
Restore a synthetic scheduling and imaging-index service into a restricted recovery environment.
Evaluate: Verify correct record associations and access controls while keeping the exercise separate from clinical operations.
What drives the operating cost
- Protected capacity, instances, users or workload subscriptions can use different license meters. Compare the exact protected estate and selected modules.
- Retained immutable copies, change rate and deduplication behavior drive storage use; locks can prevent early deletion of a mistaken retention policy.
- Cloud retrieval, transfer, temporary recovery compute and cross-region copies may add costs beyond a backup subscription.
- Exercises require application owners, recovery infrastructure and staff able to validate identity, network and application dependencies.
Questions worth asking
- Can a compromised production administrator destroy every recovery copy?
- How is a usable recovery point selected and validated?
- Which dependencies and credentials are needed before the service works?
Common assumptions to check
Immutable means the recovered data is clean.
Immutability limits changes or deletion under specified rules. It can preserve an already-compromised backup, so recovery-point selection and validation remain necessary.
Replication is automatically a backup.
Replication may carry deletions or corruption to another location. Independent retention and tested recovery points determine whether it helps this incident.
An air-gap label proves independence from a compromised administrator.
Ask which network paths, identities, keys and control planes remain shared. A virtual air gap has explicit connectivity and administration rules to verify.
APPLY THE IDEA / EVALUATION PLAN
Make the outcome observable.
Restore a fictional application into an isolated environment. Measure elapsed recovery time, reconcile data against a known baseline and test the business workflow.
Record recoverable scope and independent access.
A service map lists protected data, excluded configuration, keys, credentials, recovery owners and the target recovery objectives.
Challenge one protection assumption.
The test demonstrates a retained copy survives an authorized lab deletion attempt or a missed backup becomes visible; it records exactly which control supplied the result.
Restore and validate a complete synthetic transaction.
The operator records recovery-point age, elapsed time, application checks and unresolved dependencies in the isolated target.
Rehearse loss of the usual management path.
A documented alternative can reach the copies and required keys when the normal backup console or production identity service is unavailable.
Use synthetic data and an authorized test environment. Record scope, product edition, permissions, results, and recovery behavior.
Vendors & products
8 profilesAn editorial selection of relevant offerings, with documented scope and practical evaluation questions. Atlas Fold provides a separate provisional documentation assessment for selected offerings; inclusion in this directory is not a ranking.
Rubrik / Enterprise backup and recovery
Rubrik Security Cloud
The comparison scopes RSC-managed enterprise data protection with CDM, retention-locked SLA Domains and Orchestrated Recovery for vSphere. Cloud, SaaS, identity recovery and separate vault or simulation entitlements must be verified rather than inherited from the brand.
Cohesity / Enterprise backup and recovery
Cohesity DataProtect
This profile emphasizes self-managed DataProtect. FortKnox, Cloud Protection Service, NetBackup and RecoveryAgent require separate scope and licensing decisions; their documentation is not interchangeable with the selected DataProtect deployment.
Veeam / Enterprise backup and recovery
Veeam Data Platform
The comparison uses Premium scope: Backup & Replication 13, Veeam ONE and Recovery Orchestrator 13, with a supported hardened repository. Data Cloud SaaS backup, Kasten and separate identity products are outside this assessment.
Commvault / Enterprise backup and recovery
Commvault Cloud
The comparison covers Commvault software 11.42 backup and recovery, supported storage locking, plus separately entitled Air Gap Protect and cloud-based Cleanroom Recovery. Storage tiers, supported workloads and recovery destinations have different limits.
Dell Technologies / Isolated vaulting
Dell PowerProtect Cyber Recovery
This is the Cyber Recovery vault layer with compatible PowerProtect Data Domain infrastructure. Data Manager, other backup applications and CyberSense analysis are separate components. Verify the release-specific support matrix and deployment requirements.
Druva / Cloud and SaaS recovery
Druva Data Security Cloud
Evaluate the selected backup workloads and Cyber Resiliency entitlement. Recovery plans, curated snapshots and restore scans have workload and region limits; the March 2026 VMware recovery-plan release also identifies availability restrictions.
Acronis / Cloud and SaaS recovery
Acronis Cyber Protect Cloud
This entry uses the Cyber Protect Cloud service documentation. Provider packaging and feature availability vary. Safe recovery is limited to supported Windows machine or volume backups and does not scan non-NTFS volumes; CDP backups have a separate limitation.
HYCU / Cloud and SaaS recovery
HYCU R-Cloud
Select the exact R-Cloud edition and connector. Hybrid Cloud, Azure, Microsoft 365 and Google Workspace have separate documentation. Storage immutability, export and recovery behavior must be checked for each application and destination.